I am trying to get the Splunk integration working with my 12.4.2 system and the Dcrum CAS app for splunk, but it seems it will not work unless the account used for the Data input section has Administrator credentials. Is that by design? I know the REST stuff will work with lesser permissions.
Any body have a similar experience with this?
Solved! Go to Solution.
Yes, this is by design. The reasoning was that using this feature you are able to export any data from CAS server so you need to have high enough privileges to get into the API.
Is accessing CAS from Splunk with administrator privileges a problem in your case? Can you elaborate on this?
I really don't like having a report being run by a Administrator account. I have to provide the account to my Splunk team to setup the app, so now I have a team with an account that allows them to make changes to the DCRUM system. This is a really poor design in my opinion, and will probably cause me to abandon the solution.